+49 6151 6290246

Published: August 6, 2026

NIS2 and Supply Chain Security: Managing Third-Party Risks

This text was generated using artificial intelligence (AI).

Attackers often target not their actual target, but its service providers. The NIS2 Directive addresses this issue by requiring affected companies to actively manage the security of their supply chain. This article explains what the German implementing law specifically requires and how you can effectively manage third-party risks (as of August 2026).

In connection with NIS2, the following are often Supplier Risk Management, Vendor Risk Management (VRM), Third-Party Risk Management (TPRM) and Cyber Supply Chain Risk Management (C-SCRM) . These terms overlap, but each has a different focus: VRM focuses primarily on suppliers, TPRM covers all third parties, and C-SCRM specifically addresses cyber risks within the supply chain.

Key Points at a Glance

Why NIS2 Specifically Regulates the Supply Chain

The NIS2 Directive (EU) 2022/2555 lists supply chain security as one of the ten minimum measures for cyber risk management. Article 21(2)(d) explicitly mentions it, including the security-related aspects of relationships with direct suppliers or service providers. The German legislature has adopted this requirement almost verbatim in Section 30(2)(4) of the new BSI Act.

Recital 85 of the Directive explains the reason: There has been a rise in incidents where companies are compromised through vulnerabilities in third-party products and services. Remote maintenance access, a tampered software component, or an inadequately secured cloud service opens the door for attackers to enter otherwise well-protected networks. A company’s own firewall is of little help if a supplier with privileged access is itself vulnerable.

The NIS2 Implementation Act has been in effect in Germany since December 6, 2025, with no grace period from the very first day. According to its own statements, the BSI now oversees approximately 29,500 organizations across 18 sectors, ranging from energy and healthcare to transportation and manufacturing. Many small and medium-sized enterprises are subject to cybersecurity regulations for the first time. Our article provides a comprehensive overview of the scope of application, thresholds, and obligations: NIS2 Directive.

What the law specifically requires: assessment, contracts, monitoring

The obligation to ensure supply chain security consists of three components. First, supplier assessment: Article 21(3) of the Directive requires that the specific vulnerabilities of each direct supplier be taken into account, as well as the overall quality of its products and its cybersecurity practices, including the security of its development processes. A blanket assessment based on gut feeling does not meet this standard.

Second, contractual provisions. Security requirements are effective only if they are agreed upon in a binding manner. In practice, these include, among other things:

Third, continuous monitoring. A one-time assessment during onboarding does not provide a permanent picture of the risk landscape, because a supplier’s attack surface changes with every new system and every configuration change. Added to this is the governance level: According to Section 38 of the BSIG, management must implement risk management measures, monitor their implementation, and undergo regular training. If management violates these obligations, it is liable to its own organization for damages caused through negligence. Our overview of the NIS2 Requirements and Mandatory Measures.

Questionnaire, Security Rating, Audit: A Comparison of Three Methods

Three methods have become established for supplier evaluation; they take different perspectives and complement one another. Questionnaires assess processes and organization from the supplier’s perspective. A Security Rating measures the attack surface that is actually visible from the Internet. Audits conduct in-depth reviews of internal processes. The following overview illustrates the differences.

CriterionQuestionnaireSecurity RatingOn-site audit
PerspectiveSupplier's Self-DeclarationAn External Perspective on Realistically Attainable SystemsIn-Depth Review of Internal Processes
Cost per SupplierSteps: Create, Follow Up, EvaluateMinimal: Analysis without the supplier's involvementHigh: Preparation, Appointment, Report
TimelinessStatus as of the time of the surveycan be updated on an ongoing basisStatus as of the audit date
Objectivitydepending on self-assessmentmeasurable technical findingshigh, as verified by an independent audit
Scalability:limited by feedback and evaluationhigh, entire portfolio in parallellow, individual suppliers
Typical ApplicationsProcess and Compliance IssuesOngoing monitoring of all suppliersCritical partners with deep access

In practice, this combination has proven effective: Ratings provide an ongoing, objective basis for the entire portfolio. Questionnaires delve deeper into process-related issues with relevant partners. Audits are reserved for the few suppliers who are deeply integrated into your systems. This allows you to focus your efforts where the risk lies.

Automated Security Ratings and VRM: How to Implement Them Successfully

Anyone tasked with evaluating 50 or 200 suppliers will quickly reach capacity limits using manual methods. Automated security ratings solve this scalability problem. The analysis examines a supplier’s externally accessible systems from an attacker’s perspective, without installing agents and without the company’s involvement. The technical foundation for this is provided by External Attack Surface Management (EASM). LocateRisk provides initial results within 48 hours; after that, regular reassessments keep the picture up to date.

When it comes to supplier ratings, their reliability also depends on how up-to-date the vulnerability data is. LocateRisk uses Preemptive Intelligence, to cross-reference reports from multiple sources with a vendor’s attack surface, even if a final NVD assessment is not yet available. This makes new potential risks visible earlier, prompting a risk-based review.

Important for setting realistic expectations: The assessment reveals which of a vendor’s systems are accessible via the Internet, what software is in use there, and where configuration flaws exist. In case of doubt, the vendor itself determines whether a specific installed version is actually vulnerable. The rating provides prioritized starting points for this and makes the discussion concrete, whereas a questionnaire remains abstract.

The second component is a structured vendor risk management system. This allows you to centrally manage questionnaires, evaluate responses, store supporting documentation such as certificates, and automatically remind suppliers of outstanding responses. The combination of an external technical assessment and documented self-disclosure provides a robust overall picture for each supplier while also generating the documentation you need to present to management and regulatory authorities. To see how this works in practice, visit our page on Third Party Risk Management. LocateRisk operates the platform in compliance with the GDPR in certified German data centers, using an ISO 27001-certified ISMS.

Practical Workflow: Supply Chain Security in Five Steps

Getting started doesn't have to be a major project. With this approach, you can build the required processes step by step:

  1. Take inventory of suppliers and classify them. Identify all direct suppliers and service providers, from IT service providers to software vendors. Classify them by criticality: Who has access to your systems or data, and how quickly could a partner be replaced?
  2. Assess risks. Conduct a security assessment of your entire portfolio to establish an objective baseline. For critical suppliers, conduct a more in-depth review using a targeted questionnaire on processes, certifications, and emergency preparedness.
  3. Modify contracts. Include security requirements, incident reporting obligations, audit rights, and regulations for subcontractors in new contracts. Prioritize existing contracts based on criticality and update them upon the next renewal.
  4. Monitor continuously. Have ratings updated regularly and define thresholds at which you will take action, such as in the event of a significant deterioration in the security level. Schedule recurring reassessments for critical partners.
  5. Document and report. Document evaluations, actions, and decisions in a way that is easy to follow. Report regularly to management, as they are required to monitor implementation in accordance with § 38 BSIG and need reliable metrics to do so.

This spreads the workload out over the course of the year, and each step also generates the documentation that would be required in an emergency or during an audit.

Frequently asked questions


Indirectly, yes. Regulated companies must assess their direct suppliers and pass on security requirements through their contracts. Suppliers or IT service providers working for customers subject to NIS2 should therefore expect questionnaires, ratings, and new contract clauses. A demonstrably high level of security thus becomes a factor in sales, not just in compliance.


Questionnaires remain a useful tool, but they cover only part of the requirements. Article 21(3) of the Directive requires that the specific vulnerabilities of each direct provider and the quality of its cybersecurity practices be taken into account. This also requires a technical assessment of the actual attack surface and ongoing monitoring between survey cycles.


The legal obligation applies to direct providers and service providers—that is, your direct contractual partners. A risk-based approach makes sense here: Prioritize partners with access to systems or data, such as IT service providers, software vendors, cloud and data center operators, and maintenance companies with remote access.


Section 65 of the BSIG provides for fines of up to ten million euros for particularly important institutions, and up to 2 percent of total annual revenue for those with annual revenue exceeding 500 million euros. For important institutions, the fines are up to seven million euros or 1.4 percent, respectively. In addition, pursuant to § 38 of the BSIG in conjunction with the provisions of corporate law, management is liable to its own institution for damages caused by culpable breaches of duty.

Conclusion: From a Mandatory Requirement to a Controllable Process

NIS2 makes supply chain security a verifiable management responsibility: evaluating suppliers, incorporating requirements into contracts, and continuously monitoring compliance. With automated security ratings and structured vendor risk management, you can fulfill these obligations without significantly expanding your staff and keep track of your entire supplier portfolio. Our page shows you exactly how to get started. Vendor risk management made easy. There, you can request a demo and start evaluating your first suppliers right away.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish